CVE-2022-45406
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-45406 is a high-impact use-after-free vulnerability discovered in Mozilla Firefox's JavaScript engine. The vulnerability was reported by Samuel Groß and fixed in Firefox 107, Firefox ESR 102.5, and Thunderbird 102.5, released on November 15, 2022. The vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107 (Mozilla Advisory, CVE Details).

Technical details

The vulnerability occurs when an out-of-memory condition happens during the creation of a JavaScript global object. In this scenario, a JavaScript realm may be deleted while references to it still exist in a BaseShape. This condition leads to a use-after-free situation that could potentially result in an exploitable crash. The issue was particularly related to the garbage collection process and memory management in Firefox's JavaScript engine (Mozilla Advisory).

Impact

The vulnerability is rated as high impact. When successfully exploited, it could lead to a potentially exploitable crash of the browser, which might allow for arbitrary code execution. The vulnerability affects multiple Mozilla products including Firefox, Firefox ESR, and Thunderbird, making it a significant security concern (Mozilla Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Firefox 107, Firefox ESR 102.5, and Thunderbird 102.5. Users are advised to update their Mozilla products to these versions or newer to mitigate the risk. The fix involves modifying the lifetime management of realms to prevent them from being swept when allocated during incremental garbage collection (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69264CRITICAL9.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69263HIGH8.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69262HIGH7.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2026-21885MEDIUM6.5
  • NixOSNixOS
  • miniflux
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management